Access control

Access is granted per menu item. A role is built by ticking the screens it may reach, so it can be exactly as broad as the job actually is — and no broader.

  • Roles are built from the menu tree itself: every screen in the application is a tick box.
  • Assign a role to a user; change the role and everyone on it moves at once.
  • Hide whole modules — payroll, the general ledger, system settings — from people with no business in them.
  • Separate duties properly: the person who keys vouchers need not be the person who approves and posts them.
  • Each user still has their own login, language, number and date formats.
  • Users can be locked out without being deleted, so their history stays intact.
  • Administrators can see and change any role from System > Roles.
Role list showing a role and the menu items it excludes
Roles are built from the menu itself — this one cannot reach quotations.
An employee record showing the login field
Assign the role to the person on their own record.
User preferences screen
Everyone still keeps their own language and formats.

Every dataset on our hosting has this, from day one.

Create your free account or ask us about migrating